VulnSea

clawhub vulnerabilities

CVEs whose affected-version data names the clawhub package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

5 CVEsRSS

CVE-2026-100603Medium· 5.4
today

ClawHub (openclaw/clawhub) application/backend contains a flaw in the skill report moderation flow: four distinct ordinary authenticated accounts can report a visible skill and trigger automatic hiding (moderationStatus: hidden) of that …

ClawHub (openclaw/clawhub) application/backend contains a flaw in the skill report moderation flow: four distinct ordinary authenticated accounts can report a visible skill and trigger automatic hiding (moderationStatus: hidden) of that …

▾ Sunlitopenclaw · clawhubvia NVD
CVE-2026-100601Medium· 5.3
today

ClawHub (openclaw/clawhub) application/backend contains a server-side request forgery vulnerability in the public profile preview's image fetching

ClawHub (openclaw/clawhub) application/backend contains a server-side request forgery vulnerability in the public profile preview's image fetching. The preview accepts a user-supplied image URL and checks the textual hostname against pri…

▾ Sunlitopenclaw · clawhubvia NVD
CVE-2026-100600Medium· 5.3
today

ClawHub (the openclaw/clawhub application/backend) does not bind anonymous HTTP API requests to a trusted caller identity, so all direct anonymous API requests share a single default quota allowance

ClawHub (the openclaw/clawhub application/backend) does not bind anonymous HTTP API requests to a trusted caller identity, so all direct anonymous API requests share a single default quota allowance. A remote, unauthenticated caller can …

▾ Sunlitopenclaw · clawhubvia NVD
CVE-2026-100604Medium· 5.4
today

ClawHub (openclaw/clawhub) contains an incorrect authorization vulnerability in the ClawHub application/backend: an organization-owned skill retains the ownerUserId of its original publisher, and transfer and lifecycle authorization chec…

ClawHub (openclaw/clawhub) contains an incorrect authorization vulnerability in the ClawHub application/backend: an organization-owned skill retains the ownerUserId of its original publisher, and transfer and lifecycle authorization chec…

▾ Sunlitopenclaw · clawhubvia NVD
CVE-2026-100602Medium· 6.5
today

ClawHub (openclaw/clawhub application/backend) contains a missing authorization check in the changelog preview feature

ClawHub (openclaw/clawhub application/backend) contains a missing authorization check in the changelog preview feature. A signed-in caller can invoke the public skills:generateChangelogPreview action for a skill they are not authorized t…

▾ Sunlitopenclaw · clawhubvia NVD
clawhub vulnerabilities (CVEs) · VulnSea